michael.s.gilbert at gmail.com
Mon Nov 9 00:51:11 UTC 2009
Your package contains an embedded version of prototype.js that is
vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1)
, CVE-2008-7220 (affecting prototype.js before 22.214.171.124) , or both.
Your package embeds the following prototype.js versions:
This is a mass-filing, and the only checking done so far is a version
comparison, so please determine whether or not your package is itself
affected or not. If it is not affected please close the bug with a
message indicating this along with what you did to check.
The version of your package specified above is the earliest version
with the affected embedded code. If this version is in one or both of
the stable releases and you are affected, please coordinate with the
release team to prepare a proposed-update for your package to
There are patches available for CVE-2007-2383  and a backport for
prototypejs 1.5 for CVE-2008-7720 .
If you correct the problem in unstable, please make sure to include the
CVE number in your changelog.
Thank you for your attention to this problem.